4 ms·
This, in a nutshell, is the underutilized value of open source - the ability for the general public to conduct a trustworthy third party audit and validate secu
by aareet 13y ago
This, in a nutshell, is the underutilized value of open source - the ability for the general public to conduct a trustworthy third party audit and validate security claims of software creators.
- deleted 13y ago[deleted]
- tptacek 13y agoNot really. This is the value of crowdsourcing. The audit itself is being conducted by a professional software security firm (our sister company, as it happens) and their portion of it might only have cost a small factor more had complete source code not been available. It's the money and expertise that are making this possible, not the source code. (Don't get me wrong: I strongly prefer open source software to closed.)
- rmrfrmrf 13y agoGet outta here, party pooper!
- nabla9 13y agoI have a question. Can government issue gag order to security firm doing audit and prevent them from releasing backdoors or intentional weaknesses they discover?
- tptacek 13y agoNo.
- whyme 13y agoI'm surprised you're so confident considering how many experts were shocked to discover how far the US govt had been able to go.
- tptacek 13y agoComes from an understanding of how service providers actually get gagged: the courts actively issue a gag rule based on orders they themselves issued. That's can't be true of basic science.
- shiven 13y agoWhat if the powers that be decide to "classify" the results/reports? I would guess that would be a big legal hurdle. But if things get to that point, a copy the report would probably show up on wikileaks... I guess?
- eli 13y agoThat's not how classification works.
- tptacek 13y agoIt's also not how research works. For something to be restrained from publication, the government needs to know it exists. But with new research results, they can't know what to restrain until it's too late. They could try passing a law outlawing security research, but: good luck with that.
- geoffschmidt 13y ago
- amenod 13y agoProbably not. But they can contact a security reseach company so they make a "crowdsourced" audit project, perform it and still leave a backdoor or two uncovered. TrueCrypt gets an official audit and NSA keeps the backdoors - win-win. </sarcasm> And there is less chance that anyone else will perform an audit in near future. :(
- mafribe 13y agoI am not familiar with the legal situation. However, one needs also to consider extra-juridical means. A security company that does not comply with the demands of the relevant security services is unlikely ever to do major business again in the country where it is based.